External risk intelligence

TrueBooker WordPress Plugin Authorization Bypass Allows Account Takeover

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-14349

This vulnerability affects a WordPress plugin designed for appointment booking and scheduling. Such plugins are typically deployed on public-facing websites to allow user interaction, making the web-accessible interface the primary delivery mechanism for the application.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability exists in the TrueBooker WordPress plugin, which handles appointment bookings and scheduling. The flaw allows unauthenticated attackers to bypass authorization checks, potentially enabling them to alter user email addresses. This could lead to account takeovers, including administrator accounts, by facilitating password resets. The main concern at this stage is confirming whether this specific plugin is in use and, if so, to what extent it is exposed.

  • Attackers can change user emails without logging in.
  • Could lead to unauthorized account takeovers.
  • Confirm plugin use and exposure impact.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker can exploit this vulnerability by targeting the TrueBooker WordPress plugin. By sending specially crafted requests to the plugin's functions, an attacker can bypass authorization checks. This allows them to alter the email addresses associated with any user account on the site, potentially including administrative accounts, which can then be used to reset passwords and gain full control of the compromised account.

  • No user authentication needed to attack.
  • Attacker modifies user email addresses.
  • Risk of account takeover.

Live Threat

Current exploitation, exposure, and threat context

An unauthenticated attacker could bypass authorization checks to modify the email address of any user account on a WordPress site using the TrueBooker plugin. This could then be used to reset the account's password and take control of it.

  • User account email addresses and passwords.
  • Unauthenticated attackers could exploit the authorization bypass.
  • Account takeover and unauthorized access.

Operational Fix

Recommended remediation, mitigation, and detection steps

This critical vulnerability in the TrueBooker plugin requires immediate attention from WordPress site administrators and potentially the application owner responsible for the plugin's deployment. The first practical step is to inventory all WordPress sites using this plugin, confirm their exposure to the internet, and identify the specific business owner for each instance. This will enable a risk-based approach to remediation, prioritizing critical and accessible systems.

  • WordPress administrators own the issue.
  • Verify all WordPress sites using the plugin.
  • Plan and execute remediation in maintenance windows.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the TrueBooker plugin?

TrueBooker is a WordPress plugin designed to add appointment booking and scheduling functionality to websites. It allows site owners to manage calendars and let visitors reserve time slots, essentially acting as a bridge between your business and customers directly through your site's interface.

What does CVE-2026-14349 mean?

This vulnerability is classified as CWE-862, which is an Improper Authorization weakness. In plain terms, the plugin fails to check if a person has permission to perform a specific task before allowing it. Because of this, the system incorrectly trusts incoming requests, even if they come from someone who hasn't logged in or does not have administrator privileges.

How do attackers trigger this vulnerability?

An attacker triggers this by sending specially crafted web requests to the plugin. Because the plugin performs no validation, the attacker can change the email address of any account, including administrators. This bug does not require any pre-existing session, meaning simply having the vulnerable plugin active is enough for an unauthenticated user to attempt the change.

Is my website at risk from CVE-2026-14349?

If you run TrueBooker on an internet-facing WordPress site, you are at higher risk. According to Halo Surface Signal, because this plugin is designed for public interaction, the web-accessible interface is the primary path for attackers. Sites that are private or internal may have a lower immediate risk, but any instance accessible over a network remains a potential target for this bypass.

What should I do if I use TrueBooker?

First, perform an inventory of all WordPress installations to identify where the TrueBooker plugin is active. Once identified, confirm which sites are exposed to the internet. Because this issue allows for full account takeover, you should prioritize these systems for maintenance, check for unauthorized account changes, and apply the latest plugin updates as soon as they are available.

References